Bias Analysis
Detected Bias Types
windows_tools
windows_first
missing_linux_example
Summary
The documentation demonstrates a moderate Windows bias. Windows-specific event sources (e.g., Windows Security Events, Windows Forwarded Events) are listed explicitly, and device-related enrichments and examples predominantly reference Windows (e.g., DeviceFamily: Windows, OperatingSystem: Windows 10). There is little mention of Linux or macOS equivalents, and no examples or guidance are provided for non-Windows endpoints or logs. The documentation assumes a Windows-centric environment for device and security event analysis, which may create friction for organizations with significant Linux/macOS infrastructure.
Recommendations
- Explicitly mention support for Linux/macOS endpoints and their log sources, if available.
- Add examples and enrichment fields relevant to Linux/macOS devices (e.g., DeviceFamily: Linux, OperatingSystem: Ubuntu, macOS).
- Clarify whether UEBA supports Linux/macOS security events and how to onboard these sources.
- Provide parity in documentation tables and sample values for non-Windows operating systems.
- If Linux/macOS support is limited, clearly state the limitations and provide guidance for mixed environments.
Create Pull Request